CISA’s updated guidance calls on organizations to find internet-facing systems, remove exposure that is not operationally necessary, and place essential remote access behind managed, monitored controls.

Key takeaways

  • CISA’s guidance was originally published in June 2025 and was updated in August 2026; it is not an entirely new August 27 release.
  • Organizations should inventory public-facing assets and decide whether each exposure is genuinely required for operations.
  • Direct internet access to PLCs, HMIs, RTUs and similar OT assets should be removed or restricted wherever feasible.
  • Required vendor and operator access should be routed through a centrally managed, monitored access path with MFA, patching and strong credentials.
  • Exposure reviews must include cellular-connected equipment, contractor access paths and systems installed during commissioning or emergency maintenance.

An updated guide, not a new program

CISA has updated its Internet Exposure Reduction Guidance, a resource for organizations that operate internet-accessible IT, OT, industrial control system and connected-device assets. The underlying CISA page lists an original publication date of June 4, 2025; reporting on the current version identifies an August 21, 2026 revision. News coverage on August 26 and 27 focused on the update after CISA reported malicious activity against more than 100 internet-exposed U.S. water and wastewater systems during July 2026. ([cisa.gov](https://www.cisa.gov/resources-tools/resources/exposure-reduction?utm_source=openai))

paragraphs are not allowed

Start with the externally visible inventory

The guidance’s first operational step is to establish what can be reached from the internet. That work should cover public IP ranges, DNS records, remote-management portals, cloud-hosted services, VPN appliances, cellular routers and modems, and third-party support connections. CISA identifies publicly available discovery platforms as resources for locating exposed systems, while noting that listing them does not constitute government endorsement. ([cisa.gov](https://www.cisa.gov/resources-tools/resources/exposure-reduction?utm_source=openai))

For installers and integrators, the inventory should not stop at enterprise IT. Include cameras and recorders with remote-management features, building-management gateways, cellular-connected telemetry equipment, engineering workstations, PLCs, HMIs, remote terminal units and any device added under a vendor-maintenance arrangement. A system can become externally reachable through a carrier-assigned address or an undocumented forwarding rule even when the facility’s primary network is well controlled. This is an implementation recommendation based on CISA’s exposure-management approach. ([cisa.gov](https://www.cisa.gov/resources-tools/resources/exposure-reduction?utm_source=openai))

Remove access that has no operational purpose

CISA advises organizations to determine which internet exposures are necessary and to remove or restrict the rest, while reviewing dependencies before making changes that could affect operations. The goal is not to eliminate all remote support; it is to stop treating direct public reachability as the default design for control and management devices. ([cisa.gov](https://www.cisa.gov/resources-tools/resources/exposure-reduction?utm_source=openai))

A practical commissioning review can classify every external connection by asset owner, operational purpose, access method, authorized users, supporting vendor, approval date and expiration date. Temporary connections deserve particular attention: a maintenance path created for startup, troubleshooting or a one-time firmware update can remain available long after the immediate work is complete. The joint international OT connectivity guidance similarly recommends prompt investigation of any asset identified through an external attack-surface management or discovery service. ([ic3.gov](https://www.ic3.gov/CSA/2026/260114.pdf))

Put necessary remote access behind a controlled boundary

For systems that must remain remotely accessible, CISA recommends changing default passwords, applying current security patches, replacing unsupported software and devices, using a jump host, monitoring ingress and egress traffic, and implementing MFA where possible. Organizations should route required access through a secure gateway, firewall, VPN or another centrally managed access solution rather than exposing field control equipment directly. ([cisa.gov](https://www.cisa.gov/resources-tools/resources/exposure-reduction?utm_source=openai))

In an OT deployment, this means a remote technician should authenticate to a managed access layer and then use authorized, logged connections to reach the intended system. Direct inbound access to a controller, HMI or remote-management interface is difficult to supervise consistently and leaves little margin if a credential, configuration or device vulnerability fails. Current UK NCSC guidance likewise advises operators not to expose PLCs and HMIs directly to the public internet and to maintain supported, updated boundary devices on segregated management networks. ([ncsc.gov.uk](https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices))

Make exposure management a recurring maintenance task

CISA’s final step is routine reassessment. Exposure changes whenever equipment is replaced, an ISP or cellular service is changed, a firewall is reconfigured, or a contractor is granted access. A periodic external review should therefore be part of preventive maintenance and change-management procedures, not a one-time cybersecurity project. ([cisa.gov](https://www.cisa.gov/resources-tools/resources/exposure-reduction?utm_source=openai))

Procurement and engineering teams can support that process by requiring documented remote-access architecture, vendor support status, firmware-update ownership, named administration accounts, logging requirements and a clear removal procedure at project closeout. Where legacy equipment cannot support modern authentication or patching, the organization should record the limitation and use compensating controls such as isolation, tightly restricted access paths and monitoring while planning replacement. International OT guidance emphasizes that boundary devices should be updated, supported and replaced before end of life. ([ncsc.gov.uk](https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices))